The crypto industry has long been plagued by hacking incidents and exploits, and now artificial intelligence is exacerbating the issue. Charles Guillemet, chief technology officer at Ledger, a prominent crypto wallet provider, believes that the economics of cybersecurity are being upended as AI tools make it faster and cheaper to launch attacks on systems. Guillemet noted that identifying vulnerabilities and exploiting them has become relatively easy and inexpensive, with the cost approaching zero. His comments come amid a series of high-profile crypto heists, including the recent $285 million exploit of Solana-based DeFi protocol Drift and the $25 million attack on yield protocol Resolv.
According to data from DefiLlama, over $1.4 billion in assets were stolen or lost in crypto attacks over the past year. The traditional security approach, which relies on the idea that hacking a system should be more difficult and expensive than the potential reward, is being eroded by AI. Tasks that previously required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in seconds with the right prompts. For the crypto industry, where code often controls large pools of funds, this shift raises the stakes.
Guillemet warned that developers of blockchain protocols need to be perfect in their approach to security. The problem is further complicated by AI-generated code, which can spread vulnerabilities more quickly. Guillemet emphasized that there is no simple solution to making code secure and that a more comprehensive approach is needed.
He suggested that formal verification, which involves using mathematical proofs to validate code, is a more effective approach than traditional audits. Hardware-based security is another important layer, as devices like hardware wallets can isolate private keys from internet-connected systems, reducing exposure. Guillemet's message to average crypto users is clear: assume that systems can and will fail, and take steps to protect yourself, such as using cold storage and keeping sensitive data offline.
However, even these measures are not foolproof, and risks extend beyond software to include physical attacks targeting crypto holders. Guillemet expects that critical systems like wallets and protocols will invest heavily in security and adapt, but much of the broader software ecosystem may struggle to keep up. Ultimately, the increasing ease of hacking poses a significant challenge to the crypto industry, and a new approach to security is needed to mitigate these risks.